论文部分内容阅读
终端代码防篡改技术研究对保护网络终端安全具有重要意义,是信息安全研究的热点问题之一.在分析常见网络终端体系结构脆弱性问题的基础上,提出一种以硬件为核心的终端代码防篡改方案.该方案通过构建独立可执行环境来解决程序运行过程中的完整性保护问题,通过物理隔离和强制访问控制解决数据机密性保护问题.最终采用通用USB-KEY和部分终端代码仿真实现独立可执行设备原型,并对其主要功能和性能进行了测试.实验结果表明,该方案能够利用较低成本的硬件资源,为网络终端内目标程序提供防篡改保护.
The study of terminal code anti-tamper technology is of great significance to the protection of network terminal security and is one of the hot issues in information security research.On the basis of analyzing the vulnerability of common network terminal architecture, a hardware-based terminal code protection Tampering scheme.This scheme solves the problem of integrity protection during program running by constructing an independent executable environment and solves the problem of data confidentiality protection through physical isolation and forced access control.Finally, universal USB-KEY and partial terminal code simulation are used to achieve independence Executable prototype, and tested its main function and performance.The experimental results show that the scheme can utilize the lower cost of hardware resources to provide tamper-proof protection for the target program in the network terminal.